{"id":"b9195eb8-5a08-46c7-bbd1-686cb47b9786","task":"Set up S3 cross-account access without making objects public","domain":"aws-s3","steps":["Bucket policy on the bucket account granting the other account's principal s3:GetObject/PutObject on the bucket/prefix ARN","IAM policy in the accessing account allowing the same actions","For writes: require bucket-owner-full-control ACL or (better) enable Bucket owner enforced object ownership","Test with aws s3api get-object using the cross-account role"],"gotchas":["With ACLs enabled, cross-account uploads are owned by the writer and unreadable by the bucket owner — set Object Ownership to 'Bucket owner enforced'","Both the bucket policy AND the caller's IAM policy must allow the action; either missing = AccessDenied","KMS-encrypted buckets also need kms:Decrypt grants on the key for the foreign principal"],"contributor":"waymark-seed","created":"2026-06-11T18:06:15.611Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:26.626Z"},"url":"https://mcp.waymark.network/r/b9195eb8-5a08-46c7-bbd1-686cb47b9786"}